]>
Commit | Line | Data |
---|---|---|
dba3c1d3 PG |
1 | /* BGP FlowSpec VTY |
2 | * Copyright (C) 2018 6WIND | |
3 | * | |
4 | * FRRouting is free software; you can redistribute it and/or modify it | |
5 | * under the terms of the GNU General Public License as published by the | |
6 | * Free Software Foundation; either version 2, or (at your option) any | |
7 | * later version. | |
8 | * | |
9 | * FRRouting is distributed in the hope that it will be useful, but | |
10 | * WITHOUT ANY WARRANTY; without even the implied warranty of | |
11 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |
12 | * General Public License for more details. | |
13 | * | |
14 | * You should have received a copy of the GNU General Public License along | |
15 | * with this program; see the file COPYING; if not, write to the Free Software | |
16 | * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA | |
17 | */ | |
18 | ||
19 | #include <zebra.h> | |
20 | #include "command.h" | |
21 | ||
22 | #include "bgpd/bgpd.h" | |
23 | #include "bgpd/bgp_table.h" | |
24 | #include "bgpd/bgp_attr.h" | |
25 | #include "bgpd/bgp_ecommunity.h" | |
26 | #include "bgpd/bgp_vty.h" | |
27 | #include "bgpd/bgp_route.h" | |
28 | #include "bgpd/bgp_aspath.h" | |
29 | #include "bgpd/bgp_flowspec.h" | |
30 | #include "bgpd/bgp_flowspec_util.h" | |
31 | #include "bgpd/bgp_flowspec_private.h" | |
268e1b9b | 32 | #include "bgpd/bgp_debug.h" |
b588b642 | 33 | #include "bgpd/bgp_pbr.h" |
dba3c1d3 PG |
34 | |
35 | /* Local Structures and variables declarations | |
36 | * This code block hosts the struct declared that host the flowspec rules | |
37 | * as well as some structure used to convert to stringx | |
38 | */ | |
39 | ||
40 | static const struct message bgp_flowspec_display_large[] = { | |
41 | {FLOWSPEC_DEST_PREFIX, "Destination Address"}, | |
42 | {FLOWSPEC_SRC_PREFIX, "Source Address"}, | |
43 | {FLOWSPEC_IP_PROTOCOL, "IP Protocol"}, | |
44 | {FLOWSPEC_PORT, "Port"}, | |
45 | {FLOWSPEC_DEST_PORT, "Destination Port"}, | |
46 | {FLOWSPEC_SRC_PORT, "Source Port"}, | |
47 | {FLOWSPEC_ICMP_TYPE, "ICMP Type"}, | |
48 | {FLOWSPEC_ICMP_CODE, "ICMP Code"}, | |
49 | {FLOWSPEC_TCP_FLAGS, "TCP Flags"}, | |
50 | {FLOWSPEC_PKT_LEN, "Packet Length"}, | |
51 | {FLOWSPEC_DSCP, "DSCP field"}, | |
52 | {FLOWSPEC_FRAGMENT, "Packet Fragment"}, | |
40881800 | 53 | {FLOWSPEC_FLOW_LABEL, "Packet Flow Label"}, |
dba3c1d3 PG |
54 | {0} |
55 | }; | |
56 | ||
57 | static const struct message bgp_flowspec_display_min[] = { | |
58 | {FLOWSPEC_DEST_PREFIX, "to"}, | |
59 | {FLOWSPEC_SRC_PREFIX, "from"}, | |
60 | {FLOWSPEC_IP_PROTOCOL, "proto"}, | |
61 | {FLOWSPEC_PORT, "port"}, | |
62 | {FLOWSPEC_DEST_PORT, "dstp"}, | |
63 | {FLOWSPEC_SRC_PORT, "srcp"}, | |
64 | {FLOWSPEC_ICMP_TYPE, "type"}, | |
65 | {FLOWSPEC_ICMP_CODE, "code"}, | |
01ffd28b | 66 | {FLOWSPEC_TCP_FLAGS, "tcp"}, |
dba3c1d3 PG |
67 | {FLOWSPEC_PKT_LEN, "pktlen"}, |
68 | {FLOWSPEC_DSCP, "dscp"}, | |
69 | {FLOWSPEC_FRAGMENT, "pktfrag"}, | |
40881800 | 70 | {FLOWSPEC_FLOW_LABEL, "flwlbl"}, |
dba3c1d3 PG |
71 | {0} |
72 | }; | |
73 | ||
362a06e3 PG |
74 | #define FS_STRING_UPDATE(count, ptr, format, remaining_len) do { \ |
75 | int _len_written; \ | |
76 | \ | |
77 | if (((format) == NLRI_STRING_FORMAT_DEBUG) && (count)) {\ | |
78 | _len_written = snprintf((ptr), (remaining_len), \ | |
79 | ", "); \ | |
80 | (remaining_len) -= _len_written; \ | |
81 | (ptr) += _len_written; \ | |
82 | } else if (((format) == NLRI_STRING_FORMAT_MIN) \ | |
83 | && (count)) { \ | |
84 | _len_written = snprintf((ptr), (remaining_len), \ | |
85 | " "); \ | |
86 | (remaining_len) -= _len_written; \ | |
87 | (ptr) += _len_written; \ | |
88 | } \ | |
89 | count++; \ | |
dba3c1d3 PG |
90 | } while (0) |
91 | ||
362a06e3 PG |
92 | /* Parse FLOWSPEC NLRI |
93 | * passed return_string string has assumed length | |
94 | * BGP_FLOWSPEC_STRING_DISPLAY_MAX | |
95 | */ | |
dba3c1d3 | 96 | void bgp_fs_nlri_get_string(unsigned char *nlri_content, size_t len, |
d33fc23b | 97 | char *return_string, int format, |
1840384b PG |
98 | json_object *json_path, |
99 | afi_t afi) | |
dba3c1d3 PG |
100 | { |
101 | uint32_t offset = 0; | |
102 | int type; | |
103 | int ret = 0, error = 0; | |
104 | char *ptr = return_string; | |
105 | char local_string[BGP_FLOWSPEC_STRING_DISPLAY_MAX]; | |
106 | int count = 0; | |
107 | char extra[2] = ""; | |
108 | char pre_extra[2] = ""; | |
109 | const struct message *bgp_flowspec_display; | |
d33fc23b | 110 | enum bgp_flowspec_util_nlri_t type_util; |
362a06e3 PG |
111 | int len_string = BGP_FLOWSPEC_STRING_DISPLAY_MAX; |
112 | int len_written; | |
dba3c1d3 PG |
113 | |
114 | if (format == NLRI_STRING_FORMAT_LARGE) { | |
115 | snprintf(pre_extra, sizeof(pre_extra), "\t"); | |
116 | snprintf(extra, sizeof(extra), "\n"); | |
117 | bgp_flowspec_display = bgp_flowspec_display_large; | |
118 | } else | |
119 | bgp_flowspec_display = bgp_flowspec_display_min; | |
d33fc23b PG |
120 | /* if needed. type_util can be set to other values */ |
121 | type_util = BGP_FLOWSPEC_RETURN_STRING; | |
dba3c1d3 PG |
122 | error = 0; |
123 | while (offset < len-1 && error >= 0) { | |
124 | type = nlri_content[offset]; | |
125 | offset++; | |
126 | switch (type) { | |
127 | case FLOWSPEC_DEST_PREFIX: | |
128 | case FLOWSPEC_SRC_PREFIX: | |
129 | ret = bgp_flowspec_ip_address( | |
d33fc23b | 130 | type_util, |
dba3c1d3 PG |
131 | nlri_content+offset, |
132 | len - offset, | |
1840384b | 133 | local_string, &error, |
9cec4121 | 134 | afi, NULL); |
dba3c1d3 PG |
135 | if (ret <= 0) |
136 | break; | |
d33fc23b PG |
137 | if (json_path) { |
138 | json_object_string_add(json_path, | |
139 | lookup_msg(bgp_flowspec_display, type, ""), | |
140 | local_string); | |
141 | break; | |
142 | } | |
362a06e3 PG |
143 | FS_STRING_UPDATE(count, ptr, format, len_string); |
144 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
145 | pre_extra, | |
146 | lookup_msg(bgp_flowspec_display, | |
147 | type, ""), | |
148 | local_string, extra); | |
149 | len_string -= len_written; | |
150 | ptr += len_written; | |
dba3c1d3 | 151 | break; |
40881800 | 152 | case FLOWSPEC_FLOW_LABEL: |
dba3c1d3 PG |
153 | case FLOWSPEC_IP_PROTOCOL: |
154 | case FLOWSPEC_PORT: | |
155 | case FLOWSPEC_DEST_PORT: | |
156 | case FLOWSPEC_SRC_PORT: | |
157 | case FLOWSPEC_ICMP_TYPE: | |
158 | case FLOWSPEC_ICMP_CODE: | |
d33fc23b | 159 | ret = bgp_flowspec_op_decode(type_util, |
dba3c1d3 PG |
160 | nlri_content+offset, |
161 | len - offset, | |
162 | local_string, &error); | |
163 | if (ret <= 0) | |
164 | break; | |
d33fc23b PG |
165 | if (json_path) { |
166 | json_object_string_add(json_path, | |
167 | lookup_msg(bgp_flowspec_display, type, ""), | |
168 | local_string); | |
169 | break; | |
170 | } | |
362a06e3 PG |
171 | FS_STRING_UPDATE(count, ptr, format, len_string); |
172 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
173 | pre_extra, | |
174 | lookup_msg(bgp_flowspec_display, | |
175 | type, ""), | |
dba3c1d3 | 176 | local_string, extra); |
362a06e3 PG |
177 | len_string -= len_written; |
178 | ptr += len_written; | |
dba3c1d3 PG |
179 | break; |
180 | case FLOWSPEC_TCP_FLAGS: | |
588ec356 | 181 | ret = bgp_flowspec_bitmask_decode( |
d33fc23b | 182 | type_util, |
dba3c1d3 PG |
183 | nlri_content+offset, |
184 | len - offset, | |
185 | local_string, &error); | |
186 | if (ret <= 0) | |
187 | break; | |
d33fc23b PG |
188 | if (json_path) { |
189 | json_object_string_add(json_path, | |
362a06e3 PG |
190 | lookup_msg(bgp_flowspec_display, |
191 | type, ""), | |
d33fc23b PG |
192 | local_string); |
193 | break; | |
194 | } | |
362a06e3 PG |
195 | FS_STRING_UPDATE(count, ptr, format, len_string); |
196 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
197 | pre_extra, | |
198 | lookup_msg(bgp_flowspec_display, | |
199 | type, ""), | |
200 | local_string, extra); | |
201 | len_string -= len_written; | |
202 | ptr += len_written; | |
dba3c1d3 PG |
203 | break; |
204 | case FLOWSPEC_PKT_LEN: | |
205 | case FLOWSPEC_DSCP: | |
206 | ret = bgp_flowspec_op_decode( | |
d33fc23b | 207 | type_util, |
dba3c1d3 PG |
208 | nlri_content + offset, |
209 | len - offset, local_string, | |
210 | &error); | |
211 | if (ret <= 0) | |
212 | break; | |
d33fc23b PG |
213 | if (json_path) { |
214 | json_object_string_add(json_path, | |
215 | lookup_msg(bgp_flowspec_display, type, ""), | |
216 | local_string); | |
217 | break; | |
218 | } | |
362a06e3 PG |
219 | FS_STRING_UPDATE(count, ptr, format, len_string); |
220 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
221 | pre_extra, | |
222 | lookup_msg(bgp_flowspec_display, | |
223 | type, ""), | |
dba3c1d3 | 224 | local_string, extra); |
362a06e3 PG |
225 | len_string -= len_written; |
226 | ptr += len_written; | |
dba3c1d3 PG |
227 | break; |
228 | case FLOWSPEC_FRAGMENT: | |
588ec356 PG |
229 | ret = bgp_flowspec_bitmask_decode( |
230 | type_util, | |
231 | nlri_content+offset, | |
232 | len - offset, | |
233 | local_string, &error); | |
dba3c1d3 PG |
234 | if (ret <= 0) |
235 | break; | |
d33fc23b PG |
236 | if (json_path) { |
237 | json_object_string_add(json_path, | |
238 | lookup_msg(bgp_flowspec_display, | |
239 | type, ""), | |
240 | local_string); | |
241 | break; | |
242 | } | |
362a06e3 PG |
243 | FS_STRING_UPDATE(count, ptr, format, len_string); |
244 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
245 | pre_extra, | |
246 | lookup_msg(bgp_flowspec_display, | |
247 | type, ""), | |
248 | local_string, extra); | |
249 | len_string -= len_written; | |
250 | ptr += len_written; | |
dba3c1d3 PG |
251 | break; |
252 | default: | |
253 | error = -1; | |
254 | break; | |
255 | } | |
256 | offset += ret; | |
257 | } | |
258 | } | |
259 | ||
bd494ec5 | 260 | void route_vty_out_flowspec(struct vty *vty, const struct prefix *p, |
9b6d8fcf | 261 | struct bgp_path_info *path, int display, |
4b7e6066 | 262 | json_object *json_paths) |
dba3c1d3 PG |
263 | { |
264 | struct attr *attr; | |
265 | char return_string[BGP_FLOWSPEC_STRING_DISPLAY_MAX]; | |
c6423c31 | 266 | char *s1 = NULL, *s2 = NULL; |
d33fc23b PG |
267 | json_object *json_nlri_path = NULL; |
268 | json_object *json_ecom_path = NULL; | |
269 | json_object *json_time_path = NULL; | |
270 | char timebuf[BGP_UPTIME_LEN]; | |
7de5a4d9 | 271 | struct ecommunity *ipv6_ecomm = NULL; |
dba3c1d3 | 272 | |
c24ceb89 PG |
273 | if (p == NULL || p->family != AF_FLOWSPEC) |
274 | return; | |
275 | if (json_paths) { | |
276 | if (display == NLRI_STRING_FORMAT_JSON) | |
277 | json_nlri_path = json_object_new_object(); | |
278 | else | |
279 | json_nlri_path = json_paths; | |
dba3c1d3 | 280 | } |
c24ceb89 PG |
281 | if (display == NLRI_STRING_FORMAT_LARGE && path) |
282 | vty_out(vty, "BGP flowspec entry: (flags 0x%x)\n", | |
283 | path->flags); | |
284 | bgp_fs_nlri_get_string((unsigned char *) | |
285 | p->u.prefix_flowspec.ptr, | |
286 | p->u.prefix_flowspec.prefixlen, | |
287 | return_string, | |
288 | display, | |
289 | json_nlri_path, | |
290 | family2afi(p->u.prefix_flowspec | |
291 | .family)); | |
292 | if (display == NLRI_STRING_FORMAT_LARGE) | |
293 | vty_out(vty, "%s", return_string); | |
294 | else if (display == NLRI_STRING_FORMAT_DEBUG) | |
295 | vty_out(vty, "%s", return_string); | |
296 | else if (display == NLRI_STRING_FORMAT_MIN) | |
297 | vty_out(vty, " %-30s", return_string); | |
298 | else if (json_paths && display == NLRI_STRING_FORMAT_JSON) | |
299 | json_object_array_add(json_paths, json_nlri_path); | |
9b6d8fcf | 300 | if (!path) |
dba3c1d3 | 301 | return; |
d04ac434 | 302 | |
7de5a4d9 DA |
303 | if (path->attr) |
304 | ipv6_ecomm = bgp_attr_get_ipv6_ecommunity(path->attr); | |
305 | ||
b53e67a3 | 306 | if (path->attr && (bgp_attr_get_ecommunity(path->attr) || ipv6_ecomm)) { |
dba3c1d3 | 307 | /* Print attribute */ |
9b6d8fcf | 308 | attr = path->attr; |
b53e67a3 DA |
309 | if (bgp_attr_get_ecommunity(attr)) |
310 | s1 = ecommunity_ecom2str(bgp_attr_get_ecommunity(attr), | |
311 | ECOMMUNITY_FORMAT_ROUTE_MAP, | |
312 | 0); | |
d04ac434 DS |
313 | if (ipv6_ecomm) |
314 | s2 = ecommunity_ecom2str( | |
315 | ipv6_ecomm, ECOMMUNITY_FORMAT_ROUTE_MAP, 0); | |
c6423c31 | 316 | if (!s1 && !s2) |
dba3c1d3 PG |
317 | return; |
318 | if (display == NLRI_STRING_FORMAT_LARGE) | |
c6423c31 PG |
319 | vty_out(vty, "\t%s%s%s\n", s1 ? s1 : "", |
320 | s2 && s1 ? " " : "", s2 ? s2 : ""); | |
d33fc23b | 321 | else if (display == NLRI_STRING_FORMAT_MIN) |
c6423c31 | 322 | vty_out(vty, "%s%s", s1 ? s1 : "", s2 ? s2 : ""); |
d33fc23b PG |
323 | else if (json_paths) { |
324 | json_ecom_path = json_object_new_object(); | |
c6423c31 | 325 | if (s1) |
9a659715 | 326 | json_object_string_add(json_ecom_path, |
c6423c31 | 327 | "ecomlist", s1); |
9a659715 PG |
328 | if (s2) |
329 | json_object_string_add(json_ecom_path, | |
330 | "ecom6list", s2); | |
d33fc23b PG |
331 | if (display == NLRI_STRING_FORMAT_JSON) |
332 | json_object_array_add(json_paths, | |
333 | json_ecom_path); | |
334 | } | |
f01e580f PG |
335 | if (display == NLRI_STRING_FORMAT_LARGE) { |
336 | char local_buff[INET6_ADDRSTRLEN]; | |
337 | ||
338 | local_buff[0] = '\0'; | |
3a6290bd DA |
339 | if (p->u.prefix_flowspec.family == AF_INET |
340 | && attr->nexthop.s_addr != INADDR_ANY) | |
07380148 DA |
341 | inet_ntop(AF_INET, &attr->nexthop.s_addr, |
342 | local_buff, sizeof(local_buff)); | |
f01e580f PG |
343 | else if (p->u.prefix_flowspec.family == AF_INET6 && |
344 | attr->mp_nexthop_len != 0 && | |
345 | attr->mp_nexthop_len != BGP_ATTR_NHLEN_IPV4 && | |
346 | attr->mp_nexthop_len != BGP_ATTR_NHLEN_VPNV4) | |
07380148 DA |
347 | inet_ntop(AF_INET6, &attr->mp_nexthop_global, |
348 | local_buff, sizeof(local_buff)); | |
f01e580f PG |
349 | if (local_buff[0] != '\0') |
350 | vty_out(vty, "\tNLRI NH %s\n", | |
351 | local_buff); | |
352 | } | |
c6423c31 PG |
353 | XFREE(MTYPE_ECOMMUNITY_STR, s1); |
354 | XFREE(MTYPE_ECOMMUNITY_STR, s2); | |
dba3c1d3 | 355 | } |
9b6d8fcf | 356 | peer_uptime(path->uptime, timebuf, BGP_UPTIME_LEN, 0, NULL); |
b588b642 PG |
357 | if (display == NLRI_STRING_FORMAT_LARGE) { |
358 | vty_out(vty, "\treceived for %8s\n", timebuf); | |
359 | } else if (json_paths) { | |
d33fc23b PG |
360 | json_time_path = json_object_new_object(); |
361 | json_object_string_add(json_time_path, | |
362 | "time", timebuf); | |
363 | if (display == NLRI_STRING_FORMAT_JSON) | |
364 | json_object_array_add(json_paths, json_time_path); | |
dba3c1d3 | 365 | } |
b588b642 | 366 | if (display == NLRI_STRING_FORMAT_LARGE) { |
18ee8310 | 367 | struct bgp_path_info_extra *extra = |
9b6d8fcf | 368 | bgp_path_info_extra_get(path); |
3e3708cb | 369 | bool list_began = false; |
dba3c1d3 | 370 | |
3e3708cb | 371 | if (extra->bgp_fs_pbr && listcount(extra->bgp_fs_pbr)) { |
c26edcda | 372 | struct listnode *node; |
b588b642 PG |
373 | struct bgp_pbr_match_entry *bpme; |
374 | struct bgp_pbr_match *bpm; | |
c26edcda | 375 | struct list *list_bpm; |
b588b642 | 376 | |
c26edcda | 377 | list_bpm = list_new(); |
ce3c0614 | 378 | vty_out(vty, "\tinstalled in PBR"); |
c26edcda PG |
379 | for (ALL_LIST_ELEMENTS_RO(extra->bgp_fs_pbr, |
380 | node, bpme)) { | |
381 | bpm = bpme->backpointer; | |
382 | if (listnode_lookup(list_bpm, bpm)) | |
383 | continue; | |
384 | listnode_add(list_bpm, bpm); | |
503d1ec6 | 385 | if (!list_began) { |
c26edcda | 386 | vty_out(vty, " ("); |
503d1ec6 PG |
387 | list_began = true; |
388 | } else | |
c26edcda PG |
389 | vty_out(vty, ", "); |
390 | vty_out(vty, "%s", bpm->ipset_name); | |
c26edcda | 391 | } |
3e3708cb PG |
392 | list_delete(&list_bpm); |
393 | } | |
394 | if (extra->bgp_fs_iprule && listcount(extra->bgp_fs_iprule)) { | |
395 | struct listnode *node; | |
396 | struct bgp_pbr_rule *bpr; | |
397 | ||
398 | if (!list_began) | |
399 | vty_out(vty, "\tinstalled in PBR"); | |
ce3c0614 PG |
400 | for (ALL_LIST_ELEMENTS_RO(extra->bgp_fs_iprule, |
401 | node, bpr)) { | |
402 | if (!bpr->action) | |
403 | continue; | |
404 | if (!list_began) { | |
405 | vty_out(vty, " ("); | |
406 | list_began = true; | |
407 | } else | |
408 | vty_out(vty, ", "); | |
409 | vty_out(vty, "-ipv4-rule %d action lookup %u-", | |
410 | bpr->priority, | |
411 | bpr->action->table_id); | |
412 | } | |
3e3708cb | 413 | } |
026b0e3b PG |
414 | if (list_began) |
415 | vty_out(vty, ")\n"); | |
416 | else | |
b588b642 PG |
417 | vty_out(vty, "\tnot installed in PBR\n"); |
418 | } | |
dba3c1d3 PG |
419 | } |
420 | ||
421 | int bgp_show_table_flowspec(struct vty *vty, struct bgp *bgp, afi_t afi, | |
422 | struct bgp_table *table, enum bgp_show_type type, | |
088f1098 DS |
423 | void *output_arg, bool use_json, int is_last, |
424 | unsigned long *output_cum, unsigned long *total_cum) | |
dba3c1d3 | 425 | { |
40381db7 | 426 | struct bgp_path_info *pi; |
9bcb3eef | 427 | struct bgp_dest *dest; |
dba3c1d3 PG |
428 | unsigned long total_count = 0; |
429 | json_object *json_paths = NULL; | |
d33fc23b | 430 | int display = NLRI_STRING_FORMAT_LARGE; |
dba3c1d3 PG |
431 | |
432 | if (type != bgp_show_type_detail) | |
433 | return CMD_SUCCESS; | |
434 | ||
9bcb3eef DS |
435 | for (dest = bgp_table_top(table); dest; dest = bgp_route_next(dest)) { |
436 | pi = bgp_dest_get_bgp_path_info(dest); | |
6f94b685 | 437 | if (pi == NULL) |
dba3c1d3 | 438 | continue; |
d33fc23b PG |
439 | if (use_json) { |
440 | json_paths = json_object_new_array(); | |
441 | display = NLRI_STRING_FORMAT_JSON; | |
442 | } | |
6f94b685 | 443 | for (; pi; pi = pi->next) { |
dba3c1d3 | 444 | total_count++; |
9bcb3eef DS |
445 | route_vty_out_flowspec(vty, bgp_dest_get_prefix(dest), |
446 | pi, display, json_paths); | |
dba3c1d3 | 447 | } |
d33fc23b | 448 | if (use_json) { |
75eeda93 | 449 | vty_json(vty, json_paths); |
d33fc23b PG |
450 | json_paths = NULL; |
451 | } | |
dba3c1d3 | 452 | } |
d33fc23b | 453 | if (total_count && !use_json) |
dba3c1d3 PG |
454 | vty_out(vty, |
455 | "\nDisplayed %ld flowspec entries\n", | |
456 | total_count); | |
457 | return CMD_SUCCESS; | |
458 | } | |
459 | ||
268e1b9b PG |
460 | DEFUN (debug_bgp_flowspec, |
461 | debug_bgp_flowspec_cmd, | |
462 | "debug bgp flowspec", | |
463 | DEBUG_STR | |
464 | BGP_STR | |
465 | "BGP allow flowspec debugging entries\n") | |
466 | { | |
467 | if (vty->node == CONFIG_NODE) | |
468 | DEBUG_ON(flowspec, FLOWSPEC); | |
469 | else { | |
470 | TERM_DEBUG_ON(flowspec, FLOWSPEC); | |
471 | vty_out(vty, "BGP flowspec debugging is on\n"); | |
472 | } | |
473 | return CMD_SUCCESS; | |
474 | } | |
475 | ||
476 | DEFUN (no_debug_bgp_flowspec, | |
477 | no_debug_bgp_flowspec_cmd, | |
478 | "no debug bgp flowspec", | |
479 | NO_STR | |
480 | DEBUG_STR | |
481 | BGP_STR | |
482 | "BGP allow flowspec debugging entries\n") | |
483 | { | |
484 | if (vty->node == CONFIG_NODE) | |
485 | DEBUG_OFF(flowspec, FLOWSPEC); | |
486 | else { | |
487 | TERM_DEBUG_OFF(flowspec, FLOWSPEC); | |
488 | vty_out(vty, "BGP flowspec debugging is off\n"); | |
489 | } | |
490 | return CMD_SUCCESS; | |
491 | } | |
492 | ||
4762c213 PG |
493 | int bgp_fs_config_write_pbr(struct vty *vty, struct bgp *bgp, |
494 | afi_t afi, safi_t safi) | |
495 | { | |
496 | struct bgp_pbr_interface *pbr_if; | |
497 | bool declare_node = false; | |
498 | struct bgp_pbr_config *bgp_pbr_cfg = bgp->bgp_pbr_cfg; | |
499 | struct bgp_pbr_interface_head *head; | |
500 | bool bgp_pbr_interface_any; | |
501 | ||
8f242187 | 502 | if (!bgp_pbr_cfg || safi != SAFI_FLOWSPEC) |
4762c213 | 503 | return 0; |
8f242187 PG |
504 | if (afi == AFI_IP) { |
505 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv4); | |
506 | bgp_pbr_interface_any = bgp_pbr_cfg->pbr_interface_any_ipv4; | |
507 | } else if (afi == AFI_IP6) { | |
508 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv6); | |
509 | bgp_pbr_interface_any = bgp_pbr_cfg->pbr_interface_any_ipv6; | |
510 | } else { | |
511 | return 0; | |
512 | } | |
4762c213 PG |
513 | if (!RB_EMPTY(bgp_pbr_interface_head, head) || |
514 | !bgp_pbr_interface_any) | |
515 | declare_node = true; | |
516 | RB_FOREACH (pbr_if, bgp_pbr_interface_head, head) { | |
517 | vty_out(vty, " local-install %s\n", pbr_if->name); | |
518 | } | |
4762c213 PG |
519 | return declare_node ? 1 : 0; |
520 | } | |
521 | ||
522 | static int bgp_fs_local_install_interface(struct bgp *bgp, | |
8f242187 PG |
523 | const char *no, const char *ifname, |
524 | afi_t afi) | |
4762c213 PG |
525 | { |
526 | struct bgp_pbr_interface *pbr_if; | |
527 | struct bgp_pbr_config *bgp_pbr_cfg = bgp->bgp_pbr_cfg; | |
528 | struct bgp_pbr_interface_head *head; | |
529 | bool *bgp_pbr_interface_any; | |
530 | ||
531 | if (!bgp_pbr_cfg) | |
532 | return CMD_SUCCESS; | |
8f242187 PG |
533 | if (afi == AFI_IP) { |
534 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv4); | |
535 | bgp_pbr_interface_any = &(bgp_pbr_cfg->pbr_interface_any_ipv4); | |
536 | } else { | |
537 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv6); | |
538 | bgp_pbr_interface_any = &(bgp_pbr_cfg->pbr_interface_any_ipv6); | |
539 | } | |
4762c213 PG |
540 | if (no) { |
541 | if (!ifname) { | |
542 | if (*bgp_pbr_interface_any) { | |
543 | *bgp_pbr_interface_any = false; | |
544 | /* remove all other interface list */ | |
8f242187 | 545 | bgp_pbr_reset(bgp, afi); |
4762c213 PG |
546 | } |
547 | return CMD_SUCCESS; | |
548 | } | |
549 | pbr_if = bgp_pbr_interface_lookup(ifname, head); | |
550 | if (!pbr_if) | |
551 | return CMD_SUCCESS; | |
552 | RB_REMOVE(bgp_pbr_interface_head, head, pbr_if); | |
553 | return CMD_SUCCESS; | |
554 | } | |
555 | if (ifname) { | |
556 | pbr_if = bgp_pbr_interface_lookup(ifname, head); | |
557 | if (pbr_if) | |
558 | return CMD_SUCCESS; | |
559 | pbr_if = XCALLOC(MTYPE_TMP, | |
560 | sizeof(struct bgp_pbr_interface)); | |
561 | strlcpy(pbr_if->name, ifname, INTERFACE_NAMSIZ); | |
562 | RB_INSERT(bgp_pbr_interface_head, head, pbr_if); | |
563 | *bgp_pbr_interface_any = false; | |
564 | } else { | |
565 | /* set to default */ | |
566 | if (!*bgp_pbr_interface_any) { | |
567 | /* remove all other interface list | |
568 | */ | |
8f242187 | 569 | bgp_pbr_reset(bgp, afi); |
4762c213 PG |
570 | *bgp_pbr_interface_any = true; |
571 | } | |
572 | } | |
573 | return CMD_SUCCESS; | |
574 | } | |
575 | ||
576 | DEFUN (bgp_fs_local_install_ifname, | |
577 | bgp_fs_local_install_ifname_cmd, | |
578 | "[no] local-install INTERFACE", | |
579 | NO_STR | |
580 | "Apply local policy routing\n" | |
581 | "Interface name\n") | |
582 | { | |
583 | struct bgp *bgp = VTY_GET_CONTEXT(bgp); | |
584 | int idx = 0; | |
36de6e0e | 585 | const char *no = strmatch(argv[0]->text, "no") ? "no" : NULL; |
4762c213 PG |
586 | char *ifname = argv_find(argv, argc, "INTERFACE", &idx) ? |
587 | argv[idx]->arg : NULL; | |
588 | ||
8f242187 PG |
589 | return bgp_fs_local_install_interface(bgp, no, ifname, |
590 | bgp_node_afi(vty)); | |
4762c213 PG |
591 | } |
592 | ||
088f1098 DS |
593 | extern int bgp_flowspec_display_match_per_ip(afi_t afi, struct bgp_table *rib, |
594 | struct prefix *match, | |
595 | int prefix_check, struct vty *vty, | |
596 | bool use_json, | |
597 | json_object *json_paths) | |
63a0b7a9 | 598 | { |
9bcb3eef | 599 | struct bgp_dest *dest; |
b54892e0 | 600 | const struct prefix *prefix; |
63a0b7a9 PG |
601 | int display = 0; |
602 | ||
9bcb3eef DS |
603 | for (dest = bgp_table_top(rib); dest; dest = bgp_route_next(dest)) { |
604 | prefix = bgp_dest_get_prefix(dest); | |
63a0b7a9 PG |
605 | |
606 | if (prefix->family != AF_FLOWSPEC) | |
607 | continue; | |
608 | ||
609 | if (bgp_flowspec_contains_prefix(prefix, match, prefix_check)) { | |
6f94b685 | 610 | route_vty_out_flowspec( |
9bcb3eef | 611 | vty, prefix, bgp_dest_get_bgp_path_info(dest), |
6f94b685 DS |
612 | use_json ? NLRI_STRING_FORMAT_JSON |
613 | : NLRI_STRING_FORMAT_LARGE, | |
614 | json_paths); | |
63a0b7a9 PG |
615 | display++; |
616 | } | |
617 | } | |
618 | return display; | |
619 | } | |
620 | ||
dba3c1d3 PG |
621 | void bgp_flowspec_vty_init(void) |
622 | { | |
268e1b9b PG |
623 | install_element(ENABLE_NODE, &debug_bgp_flowspec_cmd); |
624 | install_element(CONFIG_NODE, &debug_bgp_flowspec_cmd); | |
625 | install_element(ENABLE_NODE, &no_debug_bgp_flowspec_cmd); | |
626 | install_element(CONFIG_NODE, &no_debug_bgp_flowspec_cmd); | |
4762c213 | 627 | install_element(BGP_FLOWSPECV4_NODE, &bgp_fs_local_install_ifname_cmd); |
8f242187 | 628 | install_element(BGP_FLOWSPECV6_NODE, &bgp_fs_local_install_ifname_cmd); |
dba3c1d3 | 629 | } |